Effective Date: 13 Jun 2018

Last Updated: 29 Aug 2026

Website URL: https://heroicdigital.com

Data Controller: Heroic Digital (“we,” “us,” or “our”)

1. Scope and Overview

This Privacy Policy describes how Heroic Digital collects, uses, discloses, and protects information obtained from users (“you”) across our website, mobile applications, and online services. This policy applies globally and incorporates specific disclosures required by applicable regional data protection laws, including:

  • European Union / European Economic Area (EEA), United Kingdom (UK), and Switzerland: General Data Protection Regulation (GDPR) / UK GDPR.
  • United States: California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Texas Data Privacy and Security Act (TDPSA), and other applicable US state privacy legislation.
  • Canada: Personal Information Protection and Electronic Documents Act (PIPEDA).
  • Australia: Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs).
  • Brazil: Lei Geral de Proteção de Dados (LGPD).

2. Information We Collect

A. Information Provided Directly by You

  • Identity & Contact Data: Name, email address, mailing address, telephone number, job title.
  • Account Data: Username, password, preferences, and communications settings.
  • Financial & Payment Data: Payment card details, billing address, and transaction histories (processed through secure payment gateways).
  • Communications Data: Inquiries, feedback, survey responses, or customer support interactions.

B. Information Collected Automatically

  • Technical Data: IP address, browser type and version, operating system, device identifiers, time zone setting, location data, and hardware specifications.
  • Usage Data: Pages viewed, click paths, time spent on pages, referral URL, and exit pages.

C. Information Collected from Third Parties

  • Data Aggregators & Partners: Marketing and analytics data from advertising networks and public sources.

3. Legal Bases for Processing (EEA, UK, & Global Standards)

We process your personal data under the following legal bases:

  1. Consent: You have given clear consent for us to process your personal data for a specific purpose (e.g., subscribing to a newsletter, non-essential cookies).
  2. Contractual Necessity: Processing is necessary to fulfill a contract with you (e.g., delivering products, managing account access).
  3. Legitimate Interests: Processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights (e.g., fraud prevention, site security, analytics).
  4. Legal Obligation: Processing is required to comply with statutory or regulatory requirements (e.g., tax record-keeping).

4. Cookies, Analytics, and Advertising Technologies

We use cookies, web beacons, pixels, and similar technologies to enhance functionality, analyze performance, and deliver personalized advertising.

A. First-Party and Essential Cookies

Required for core website functionality, security, and network management. These cannot be disabled in our systems.

B. Third-Party Analytics Tools

  • Google Analytics (GA4): We use Google Analytics to analyze website traffic and user engagement. Google processes IP addresses in truncated/anonymized formats where required by law. You can opt out via the Google Analytics Opt-Out Browser Add-On.

C. Advertising & Retargeting Technologies

  • Meta Pixel (Facebook/Instagram): Measures conversion rates, builds targeted audiences, and delivers customized advertisements based on browsing behavior.
  • Google Ads & Remarketing: Delivers interest-based ads based on prior interactions with our site.

D. Cookie Consent Management

Upon visiting our website, a Cookie Consent Banner allows you to accept, reject, or customize non-essential cookies (Analytics, Targeting, and Functional Cookies). You may update your cookie preferences at any time by clicking the “Cookie Settings” link in our website footer.

5. Third-Party Data Sharing and Service Providers

We do not sell personal data for monetary consideration in the traditional sense. We share data only with the following categories of service providers under strict data protection agreements:

  • Hosting and Infrastructure Services: Cloud hosting providers, servers, and content delivery networks (CDNs).
  • Payment Processors: PCI-DSS compliant gateways (e.g., Stripe, PayPal).
  • Analytics & Advertising Partners: Analytics platforms, social media networks, and ad networks.
  • Operations & Support: Customer service platforms, CRM systems, and email distribution services.
  • Legal & Regulatory Authorities: Disclosed when mandated by law enforcement, court orders, or subpoenas.

6. International Data Transfers

Your personal information may be transferred to, stored, and processed in countries outside your country of residence (including the United States). When transferring data across borders:

  • Standard Contractual Clauses (SCCs): We rely on European Commission-approved SCCs (and UK Addenda) for transfers out of the EEA/UK to third countries.
  • Adequacy Decisions: Transfers are conducted to jurisdictions recognized as providing an adequate level of data protection by relevant data authorities.

7. Data Retention & Security

  • Retention: We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with legal/statutory requirements, or resolve disputes.
  • Security Measures: We implement industry-standard physical, technical, and administrative security measures (e.g., TLS/SSL encryption, access restrictions, multi-factor authentication) to protect data from unauthorized access, disclosure, or loss.

8. Children’s Privacy

Our services are not intended for individuals under 16 years of age (or 13 depending on local jurisdiction). We do not knowingly collect or solicit personal information from children. If we learn that we have collected personal data from a child without verified parental consent, we will delete that information immediately.

9. Region-Specific Disclosures & Rights

A. Rights for EEA, UK, and Swiss Residents (GDPR)

Under the GDPR, you have the following rights:

  • Right of Access: Request a copy of your personal data.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data under certain conditions.
  • Right to Restrict Processing: Request limited processing of your personal data.
  • Right to Data Portability: Request transfer of your data to another controller in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests or direct marketing.
  • Right to Withdraw Consent: Withdraw previously granted consent at any time without affecting prior lawful processing.
  • Supervisory Authority: Right to lodge a complaint with your local Data Protection Authority (DPA).

B. Rights for US Residents (California CCPA/CPRA, Virginia, Colorado, Connecticut, Texas, etc.)

This section applies to residents of US states with applicable comprehensive privacy legislation.

1. Categories of Personal Information Collected in the Past 12 Months

  • Identifiers (e.g., name, email address, IP address).
  • Commercial information (e.g., purchase history, payment records).
  • Internet or network activity (e.g., interaction with our website/ads).
  • Geolocation data.

2. Disclosure, Sale, or Sharing of Personal Information

  • We do not sell personal information for monetary value.
  • Under the California CPRA, using cross-context behavioral advertising tools (such as Meta Pixel or Google Analytics) may be defined as “Sharing” or “Selling” personal information.
  • Opt-Out Rights: You have the right to opt out of the “Sale” or “Sharing” of personal information or targeted advertising.
  • Global Privacy Control (GPC): We recognize opt-out preference signals from web browsers enabled with Global Privacy Control (GPC).

3. US State Resident Rights

  • Right to Know / Access: Request disclosure of categories and specific pieces of personal information collected.
  • Right to Delete: Request deletion of personal information collected from you.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Limit Use of Sensitive Personal Information: Limit processing of sensitive data (if applicable).
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.

To submit a request, use our [Opt-Out Form Link / Contact Information] below.

C. Rights for Canadian Residents (PIPEDA)

  • You have the right to access, challenge, and correct personal information held by us.
  • You may withdraw consent for data collection or marketing at any time, subject to legal or contractual restrictions.

D. Rights for Australian Residents (Privacy Act 1988)

  • You may request access to, or correction of, personal information held about you.
  • If you believe we have breached the Australian Privacy Principles, you may lodge a complaint using the contact information below. If unsatisfied, you may escalate the complaint to the Office of the Australian Information Commissioner (OAIC).

E. Rights for Brazilian Residents (LGPD)

  • You have rights to confirm processing, access data, correct incomplete or outdated data, anonymize, block, or eliminate unnecessary data, and revoke consent.

10. How to Exercise Your Privacy Rights

To exercise any of the rights described above, please contact us using one of the following methods:

We will verify your identity before processing your request by matching details provided in your request against data in our system. You may designate an authorized agent to submit requests on your behalf, subject to written verification. We respond to all valid requests within the timelines mandated by applicable law (e.g., 30 days for GDPR, 45 days for CCPA).

11. Changes to This Privacy Policy

We reserve the right to update this Privacy Policy to reflect changes in legal obligations, technology, or business practices. Any updates will be posted on this page with a revised “Last Updated” date. Significant material changes will be communicated via email or a prominent banner on our site.

12. Contact Information and Data Protection Officer

If you have questions, concerns, or complaints about this Privacy Policy or our data processing practices, please contact:

Data Controller / Business Contact / EU / UK Representative / Data Protection Officer (DPO):

Heroic Digital

Attn: Privacy / Compliance Department

PO Box 791

Toowong QLD 4066

Email: [email protected]

Phone: 1300 846 634